Slashdot Mirror


Hacking Group 'OurMine' Temporarily Redirected WikiLeaks DNS Service (theguardian.com)

An anonymous reader quotes the Guardian: WikiLeaks suffered an embarrassing cyber-attack when Saudi Arabian-based hacking group OurMine took over its web address. The attack saw visitors to WikiLeaks.org redirected to a page created by OurMine which claimed that the attack was a response to a challenge from the organisation to hack them.

But while it may have been humiliating for WikiLeaks, which prides itself on technical competency, the actual âoehackâ appears to have been a low-tech affair: the digital equivalent of spray-painting graffiti on the front of a bank then claiming to have breached its security. The group appears to have carried out an attack known as "DNS poisoning" for a short while on Thursday morning. Rather than attacking WikiLeaks' servers directly, they have convinced one or more DNS servers...to alter their records. For a brief period, those DNS servers told browsers that wikileaks.org was actually located on a server controlled by OurMine.

6 of 83 comments (clear)

  1. https really? by F.Ultra · · Score: 2

    I'm more interested in the point that the screenshot from the link shows a https link so either the screen shot is fake or they also managed to get hold of a certificate for wikileaks.org

  2. Re: Saudi Arabians hate WikiLeaks? by stephanruby · · Score: 2

    Wikileaks actually invited hackers to hack its site. So, I do not think that the hackers were malicious. If nothing else, they did Wikileaks a favor. If a bunch of hackers can do this, the NSA (and other intelligence agencies) can do much worse.

    Plus, an intelligence service won't attack when it's invited to do so, it will only attack when Wikileaks is about to dump something that is important to them. In this age of short attention spans, timing can be crucial.

    The same goes for Wikileaks. Wikileaks chooses to release information when it thinks it will have the most impact (e.g. just before an election, just before a troop redeployment, not during a Super Bowl, not when Beyonce is having twins, etc).

  3. No DNSSEC, what did they expect? by Anonymous Coward · · Score: 3, Informative

    Wikileaks doesn't have DNSSEC enabled, so it is trivial to poison caches. Granted, most users are not behind dnssec-validating resolvers, but this is changing...

    1. Re:No DNSSEC, what did they expect? by manu0601 · · Score: 2

      I was about to post something along that lines.

      Indeed, DNSSEC validation is not widespread, but it already improve security of the one that use it. Wikileaks can be blamed for boasting about security while missing this security feature.

  4. Re:Double standards need to be eliminated by DRJlaw · · Score: 2

    If Nazi websites are being taken down and their domains are being terminated, why do other terrorist organizations like Wikileaks get a double standard?

    Because they don't actively adopt, encourage, and support a Nazi ideology? Or racist or religious hate in general? There's no double standard - one group actively goes way over any reasonable line, and the other at worst tolerates borderline postings by others -- if even that.

    Seize their domain like you did to the Nazis.

    Nobody seized a domain. DailyStormer was free to transfer their domain to registrar would take it. They simply failed to find a taker. Look up the whois record yourself.

    let's point out that liberals demanded that Trump condemn white supremacy after the Charlottesville attacks

    Damn people for expecting their political leadership to condemn domestic terrorism and groups that endorse it through bullshit like "rahowa."

    Next time Muslims commit a terrorist attack, liberals need to condemn Islam. Eliminate these double standards.

    Conservatives already do it. Liberals will not because, as they explain over, and over, and over again, you can no more blame Islam and Muslims for those attacks than you can blame Christianity and Southern Baptists. You need to be a bit more specific, like blaming Nazis and ISIS.

    Pretty sure liberals have been blaming ISIS. So suck it.

  5. no DNSSEC so expect MITM by johnjones · · Score: 3, Informative

    The Saudi authority have for a long time performed MITM on the nations whole population and companies such as Symantec have actively aided them.

    If they had deployed DNSSec and I would have advised DANE then this would have been harder to perform.

    https://www.icann.org/resources/pages/dnssec-qaa-2014-01-29-en

    top tip try and enable it on your own domain !